GetDotted Domains

Viewing Thread:
"Filezilla FTP client - adware/malware *warning*. SourceForge!"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Thu 18/02/16 at 15:44
Moderator
"Are you sure?"
Posts: 5,000
I've been using Filezilla for years now - it's a decent open source FTP program.

Unfortunately, it seems all good things come to an end!

I was recently setting up a shiny new laptop and this included installing Filezilla. All went well and within a few minutes I was up and running. ...But the next time I went to use the PC I found that my browser(s) had been hijacked with some type of Yahoo! search page?!

Poking around I found addons in Chrome, Firefox and MS Edge for "Search Know"!

Looking though the Windows logs I was able to see this arrived on the same day I installed Filezilla!

A quick Google for Filezilla malware showed that I had been caught out by trusting a previously decent product! :¬(

It looks like this affects both Windows and MAC computers.

I got my browsers back to normal by removing all the dodgy 'Search Know' addons and removing the program using the normal Windows 'remove programs' options.

There are many reports about the dodgy behaviour of the Filezilla people. It looks like they have sold out. This started a few years ago by having 'opt out' options for programs packaged with the install file. But as time has moved on they are no longer avoidable if you use their 'recommended' download route!

They host the install files on SourceForge. This also used to be a trustworthy site - lots of daft ads, but safe if you clicked the real 'download' for the file you were looking for. Unfortunately in the last year or so they have become untrustworthy and bundle all sorts of malware and PUPs (potentially unwanted programs) in their downloads! A number of legit open source software producers have been caught out with the change within SourceForge and have moved away from them!

Here's a Filezilla forum thread that shows the issue (there are many more threads) and mentions how you can avoid the malware by not using Filezilla's 'recommended' download link! But going by their behaviour, this has put me off Filezilla somewhat!

So Filezilla users be careful if you are going to re-install it - I wish I had read a post like this before I did!

Also be aware of issues with SourceForge.
OpenOffice also host their files with them - as far as I can see their direct install is still safe, but that could change!

Finally, I was disappointed that the browsers were so easily hijacked. These days this is supposed to be harder. I guess an install program can still do whatever it wants. Google have made a lot of noise in the last year or so about how Chrome won't allow rogue addons to be installed - it looks like they've still go some work to do!

[s]Hmmm...[/s]

I've added a comment as a "heads up" to Freeola's Filezilla support page.

EDIT:
WinSCP sounds like a popular alternative to Filezilla.
Lots of people burnt by Filezilla's behaviour seem to have moved to them. If anyone uses this please post your experiences - I'll do the same if I end up using it :¬)
Thu 18/02/16 at 19:53
Regular
"Feather edged ..."
Posts: 8,536
Nice heads up Hmmm ...

I use this Core FTP if that's any help.
Thu 18/02/16 at 17:09
Moderator
"Are you sure?"
Posts: 5,000
Reading more about the problems at SourceForge I've found that they've just been acquired by new owners and one of the first things they've done is to scrap DevShare. This was scheme that was bundling the bad software.

Reading their blog entry (9th Feb 2016) they say they are trying to get their reputation back - the comments sound like the damage might be hard to repair!

[s]Hmmm...[/s]
Thu 18/02/16 at 15:44
Moderator
"Are you sure?"
Posts: 5,000
I've been using Filezilla for years now - it's a decent open source FTP program.

Unfortunately, it seems all good things come to an end!

I was recently setting up a shiny new laptop and this included installing Filezilla. All went well and within a few minutes I was up and running. ...But the next time I went to use the PC I found that my browser(s) had been hijacked with some type of Yahoo! search page?!

Poking around I found addons in Chrome, Firefox and MS Edge for "Search Know"!

Looking though the Windows logs I was able to see this arrived on the same day I installed Filezilla!

A quick Google for Filezilla malware showed that I had been caught out by trusting a previously decent product! :¬(

It looks like this affects both Windows and MAC computers.

I got my browsers back to normal by removing all the dodgy 'Search Know' addons and removing the program using the normal Windows 'remove programs' options.

There are many reports about the dodgy behaviour of the Filezilla people. It looks like they have sold out. This started a few years ago by having 'opt out' options for programs packaged with the install file. But as time has moved on they are no longer avoidable if you use their 'recommended' download route!

They host the install files on SourceForge. This also used to be a trustworthy site - lots of daft ads, but safe if you clicked the real 'download' for the file you were looking for. Unfortunately in the last year or so they have become untrustworthy and bundle all sorts of malware and PUPs (potentially unwanted programs) in their downloads! A number of legit open source software producers have been caught out with the change within SourceForge and have moved away from them!

Here's a Filezilla forum thread that shows the issue (there are many more threads) and mentions how you can avoid the malware by not using Filezilla's 'recommended' download link! But going by their behaviour, this has put me off Filezilla somewhat!

So Filezilla users be careful if you are going to re-install it - I wish I had read a post like this before I did!

Also be aware of issues with SourceForge.
OpenOffice also host their files with them - as far as I can see their direct install is still safe, but that could change!

Finally, I was disappointed that the browsers were so easily hijacked. These days this is supposed to be harder. I guess an install program can still do whatever it wants. Google have made a lot of noise in the last year or so about how Chrome won't allow rogue addons to be installed - it looks like they've still go some work to do!

[s]Hmmm...[/s]

I've added a comment as a "heads up" to Freeola's Filezilla support page.

EDIT:
WinSCP sounds like a popular alternative to Filezilla.
Lots of people burnt by Filezilla's behaviour seem to have moved to them. If anyone uses this please post your experiences - I'll do the same if I end up using it :¬)

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Everybody thinks I am an IT genius...
Nothing but admiration. I have been complimented on the church site that I manage through you and everybody thinks I am an IT genius. Your support is unquestionably outstanding.
Brian
My website looks tremendous!
Fantastic site, easy to follow, simple guides... impressed with whole package. My website looks tremendous. You don't need to be a rocket scientist to set this up, Freeola helps you step-by-step.
Susan

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.